Splunk Enterprise Security

[Splunk Content] Xp_cmdshell enablement rule error in content management

nooproblems
New Member

On Splunk ES I’m having an issue with the rule “Windows SQL Server xp_cmdshell Config Change” (https://research.splunk.com/endpoint/5eb76fe2-a869-4865-8c4c-8cff424b18b1/).
After enabling it, I can no longer disable or delete the rule.

I created a custom rule equivalent to that one with the search:
index=wineventlog EventCode=15457 "*xp_cmdshell*"
and it encounters the same issue. Even when I manually run the search
index=wineventlog EventCode=15457 "*xp_cmdshell*",
Splunk reports an error. I’m not sure what the underlying issue is. I’m wondering if anyone has encountered this problem before.

Please help me disable or delete this rule, and let me know what the root cause of the issue might be.

nooproblems_0-1764258932428.png

nooproblems_1-1764258964171.png

 

 

Tags (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @nooproblems 

It seems there is something odd going on with the response received from the API call to disable the rule, can you open the browser's Developer Console and click the Network tab, then try the disable action and see if you see a non-200 status API call, if you click in the Response tab is there anything which indicates what could be going on? 

It could be a coincidence that its since enabling this rule (but not necessarily!) but the output from the API call would be helpful in determining the issue.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...